Exploits / Vulnerability Discovered : 2022-04-07 |
Type : webapps |
Platform : php
This exploit / vulnerability Qdpm 9.2 crosssite request forgery (csrf) is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: qdPM 9.2 - Cross-site Request Forgery (CSRF)
# Google Dork: NA
# Date: 03/27/2022
# Exploit Author: Chetanya Sharma @AggressiveUser
# Vendor Homepage: https://qdpm.net/
# Software Link: https://sourceforge.net/projects/qdpm/files/latest/download
# Version: 9.2
# Tested on: KALI OS
# CVE : CVE-2022-26180
#
---------------
Steps to Exploit :
1) Make an HTML file of given POC (Change UserID field Accordingly)and host it.
2) send it to victim.